2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10544 | — | — | 1.3% | May 31, 2018 | uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate... |
| CVE-2016-10543 | — | — | 1.2% | May 31, 2018 | call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 tha... |
| CVE-2016-10542 | — | — | 7.5% | May 31, 2018 | ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date ... |
| CVE-2016-10541 | CRITICAL | 9.8 | 2.2% | May 31, 2018 | The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shel... |
| CVE-2016-10540 | — | — | 1.7% | May 31, 2018 | Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The ... |
| CVE-2016-10539 | — | — | 1.4% | May 31, 2018 | negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Ko... |
| CVE-2016-10538 | — | — | 1.0% | May 31, 2018 | The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allo... |
| CVE-2016-10537 | — | — | 0.7% | May 31, 2018 | backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events ... |
| CVE-2016-10536 | — | — | 1.0% | May 31, 2018 | engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-dire... |
| CVE-2016-10535 | — | — | 1.3% | May 31, 2018 | csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail... |
| CVE-2016-10534 | — | — | 1.0% | May 31, 2018 | electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with ... |
| CVE-2016-10533 | — | — | 1.4% | May 31, 2018 | express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mon... |
| CVE-2016-10532 | — | — | 2.4% | May 31, 2018 | console-io is a module that allows users to implement a web console in their application. A malicious user could bypass ... |
| CVE-2016-10531 | — | — | 1.5% | May 31, 2018 | marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parse... |
| CVE-2016-10530 | — | — | 1.3% | May 31, 2018 | The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can oft... |
| CVE-2016-10529 | — | — | 0.5% | May 31, 2018 | Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to mak... |
| CVE-2016-10528 | — | — | 1.2% | May 31, 2018 | restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Re... |
| CVE-2016-10527 | — | — | 1.6% | May 31, 2018 | The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable unde... |
| CVE-2016-10526 | — | — | 1.6% | May 31, 2018 | A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it di... |
| CVE-2016-10524 | HIGH | 8.2 | 0.8% | May 31, 2018 | i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API e... |
| CVE-2016-10523 | — | — | 2.5% | May 31, 2018 | MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS... |
| CVE-2016-10521 | HIGH | 7.5 | 1.1% | May 31, 2018 | jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in t... |
| CVE-2016-10520 | HIGH | 7.5 | 1.2% | May 31, 2018 | jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. |
| CVE-2016-10519 | — | — | 1.6% | May 31, 2018 | A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a... |
| CVE-2016-10518 | — | — | 2.0% | May 31, 2018 | A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memo... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now